Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfsense 2.4.4p3 - IPv6 on bridged interfaces not working...

    Scheduled Pinned Locked Moved IPv6
    20 Posts 4 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • kiokomanK
      kiokoman LAYER 8
      last edited by kiokoman

      make a screeshot of your dhcpv6 server and interfaces eventualy me and @johnpoz have he.net ipv6 configured on our pfsense and it's working without problem, must be some misconfiguration somewhereImmagine.jpg
      Immagine2.jpg
      Immagine3.jpg

      ps: that fix is really really old

      ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
      Please do not use chat/PM to ask for help
      we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
      Don't forget to Upvote with the 👍 button for any post you find to be helpful.

      1 Reply Last reply Reply Quote 0
      • T
        tomeq82
        last edited by

        fix is old, but without it, there is no link-local addresses for interfaces on the bridge.... and nothing will virtually work at all in that kind o setup.

        Comparing your screens, this is exactly the same setup. Just keep in mind that my "primary" interface LAN has all IP information needed, while LAN2 and LAN3 are bound with LAN as BRIDGE0 (pure L2 bridge, no L3 config)

        1 Reply Last reply Reply Quote 0
        • kiokomanK
          kiokoman LAYER 8
          last edited by kiokoman

          ah i understand
          i was checking the process
          dhcp is launched like this

          /usr/local/sbin/dhcpd -6 -user dhcpd -group _dhcp -chroot /var/dhcpd -cf /etc/dhcpdv6.conf -pf /var/run/dhcpdv6.pid ix0 ix0.30 ix0.20 ix0.100 igb1
          

          my guess is that it's not serving your LAN2 / LAN3 but only LAN even if it's set as a L2
          but than again.. if it was that, you should have problem even with ipv4 ....
          let's see what we can find out until someone come to the rescue

          did you try any packet capture ?

          ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
          Please do not use chat/PM to ask for help
          we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
          Don't forget to Upvote with the 👍 button for any post you find to be helpful.

          1 Reply Last reply Reply Quote 0
          • kiokomanK
            kiokoman LAYER 8
            last edited by

            advanced configuration of the bridge
            Immagine.jpg

            ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
            Please do not use chat/PM to ask for help
            we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
            Don't forget to Upvote with the 👍 button for any post you find to be helpful.

            T 1 Reply Last reply Reply Quote 0
            • T
              tomeq82 @kiokoman
              last edited by

              @kiokoman it is set, but it doesn't do anything than set the flag "auto linklocal" (patch to make link local address is STILL needed!)

              1 Reply Last reply Reply Quote 0
              • kiokomanK
                kiokoman LAYER 8
                last edited by

                i'm replicating your config on my virtual machine, i have the same behavior.
                ipv4 work on all interface, ipv6 only on LAN

                ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                Please do not use chat/PM to ask for help
                we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                1 Reply Last reply Reply Quote 0
                • kiokomanK
                  kiokoman LAYER 8
                  last edited by kiokoman

                  i get an adress if i configure a /64 but dhcpv6 still not working idk if it's a bug or what

                  ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                  Please do not use chat/PM to ask for help
                  we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                  Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                  T 1 Reply Last reply Reply Quote 0
                  • T
                    tomeq82 @kiokoman
                    last edited by

                    @kiokoman exactly. Only slac works and only for /64 prefixes (which is obvious) DHCPv6 works only on first interface of the bridge

                    1 Reply Last reply Reply Quote 0
                    • kiokomanK
                      kiokoman LAYER 8
                      last edited by

                      i can't find a way out ...
                      what i found with packet capture is that there is no answer from dhcp
                      from console i use struss against the running dhcp. it see request coming from dhclient -4 but it see nothing coming from dhclient -6

                      ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                      Please do not use chat/PM to ask for help
                      we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                      Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                      T 1 Reply Last reply Reply Quote 0
                      • T
                        tomeq82 @kiokoman
                        last edited by

                        @kiokoman when you assign shorter network for each one of the interfaces from the bridge it will work. But will work randomly. This is apparently a bug but...

                        1 Reply Last reply Reply Quote 0
                        • DerelictD
                          Derelict LAYER 8 Netgate
                          last edited by

                          Interfaces get a /64. Anything else is nonsense.

                          Chattanooga, Tennessee, USA
                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                          1 Reply Last reply Reply Quote 0
                          • kiokomanK
                            kiokoman LAYER 8
                            last edited by

                            yes, well i was testing with prefix set to /64 for the interface but i don't understand why dhcpv6 is unreacheable

                            ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                            Please do not use chat/PM to ask for help
                            we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                            Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                            1 Reply Last reply Reply Quote 0
                            • T
                              tomeq82
                              last edited by

                              Yes, despite the prefix set (/64 or any else) DHCPv6 doesn't work over bundled interfaces. It should normally as it does for DHCPv4. I have floating rule allowing all traffic in the lan area so it is no issue either here...

                              BTW, shorter prefixes are used widely in the enterprises, this is not nonsense.

                              JKnottJ 1 Reply Last reply Reply Quote 0
                              • JKnottJ
                                JKnott @tomeq82
                                last edited by

                                @tomeq82 said in pfsense 2.4.4p3 - IPv6 on bridged interfaces not working...:

                                BTW, shorter prefixes are used widely in the enterprises, this is not nonsense.

                                Not on the LAN, where /64 must be used. The shorter prefixes are split by routers, eventually winding up at /64s. For example, I get a /56 from my ISP, which I can split up into 256 /64s. I could, if needed, spit it into other prefixes, for routing elsewhere, before getting to the /64s.

                                PfSense running on Qotom mini PC
                                i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                                UniFi AC-Lite access point

                                I haven't lost my mind. It's around here...somewhere...

                                T 1 Reply Last reply Reply Quote 0
                                • T
                                  tomeq82 @JKnott
                                  last edited by

                                  @JKnott Correct, nevertheless - in this scenario it doesn't really matter. /64 is not hard limit in any kind (only if you use SLAAC it is "must")

                                  JKnottJ DerelictD 2 Replies Last reply Reply Quote 0
                                  • JKnottJ
                                    JKnott @tomeq82
                                    last edited by

                                    @tomeq82 said in pfsense 2.4.4p3 - IPv6 on bridged interfaces not working...:

                                    @JKnott Correct, nevertheless - in this scenario it doesn't really matter. /64 is not hard limit in any kind (only if you use SLAAC it is "must")

                                    From RFC4291

                                    " For all unicast addresses, except those that start with the binary
                                    value 000, Interface IDs are required to be 64 bits long and to be
                                    constructed in Modified EUI-64 format."

                                    PfSense running on Qotom mini PC
                                    i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                                    UniFi AC-Lite access point

                                    I haven't lost my mind. It's around here...somewhere...

                                    1 Reply Last reply Reply Quote 1
                                    • DerelictD
                                      Derelict LAYER 8 Netgate @tomeq82
                                      last edited by

                                      @tomeq82 well aware that interfaces may be set to prefixes longer than /64 in certain router-to-router links, etc. That is not what is being discussed here. Interfaces with hosts on them need to be /64.

                                      Chattanooga, Tennessee, USA
                                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                      1 Reply Last reply Reply Quote 1
                                      • N netblues referenced this topic on
                                      • N netblues referenced this topic on
                                      • N netblues referenced this topic on
                                      • First post
                                        Last post
                                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.